Law Enforcement Request Guidelines

Last updated on 22 August 2026

These guidelines provide instructions and greater transparency regarding the handling of law enforcement, national security, and other regulatory bodies (“Requesting Agencies”) requests for information from Kinfide Inc. (“we,” “us,” or “our”) about our users ("User Information").

We evaluate all requests strictly under the rule of law, local constitutional protections, and the fundamental technical realities of our Zero-Knowledge Architecture.

1. Critical Technical Limitations (Zero-Knowledge Architecture)

Before submitting a request, Requesting Agencies must understand our platform limitations:

  • No Access to Vault Content:All contents of a user’s vault (including files, passwords, documents, and notes) are encrypted client-side on the user’s device before reaching our servers. Our platform is designed to ensure that users' data is kept private and protected, from Kinfide and from anyone else.
  • Inability to Decrypt: It is technically impossible for us to decrypt vault contents, or bypass the encrypted contents of users’ vaults, as we do not store or hold users’ master passwords, and cannot access users’ decryption keys.
  • What We Cannot Provide: Consequently, no one at Kinfide has the ability to decrypt the contents of users’ vaults on Kinfide’s servers and we cannot provide any information regarding the content of a user’s vault in response to a request.

Wherever possible, Kinfide believes that the Requesting Agency should first seek to obtain information directly from the user who is the subject of the investigation before requesting such information from Kinfide.

2. Information That May Be Available

We minimize data retention to the absolute minimum. The only non-encrypted data we may retain and legally produce consists of basic user metadata:

  • Account creation date and time
  • Account status (active/suspended)
  • Masked billing metadata (transaction timestamps, currency type, and payment processor references). Note: Full financial data must be subpoenaed directly from the payment processor.

3. Information Requesting Agencies Must Provide

To ensure that any requests for User Information be reasonable in scope and narrowly tailored to request only the information needed to complete their investigation, the request must include valid warrant, subpoena, court order, equivalent legal process, or emergency situation submitted in its original form as an unedited PDF issued by the appropriate authority.

The request should include as much detail as possible to help us respond in an effective and timely manner. Please note: Most User Information and account can only be identified by a user's e-mail address. Therefore, the e-mail address associated with the account is the most helpful identifying information.

Each request must also include contact information for the authorized requester, including:

  • Name
  • Badge/identification number (if applicable)
  • Employer-issued e-mail address
  • Phone number, including any extension
  • Mailing address
  • Requested response date

4. Processing Requests

Upon receipt of a request for User Information, we take the following steps before responding:

  • Authority. We will review and verify that the requester has appropriate authority under applicable law to request the User Information. Absent a valid warrant, subpoena, court order, equivalent legal process, or emergency situation, it is our position not to provide User Information to a Requesting Agency.
  • Scope. Wherever possible, we will seek to ensure that any request for User Information is reasonable in scope and limited to a specific account. We may request additional context if the nature of the investigation is unclear and may object to the request when appropriate. In the event we do provide any information that may be available (as specified in Paragraph 2 above), we will seek to share only the minimum amount of information required to comply with the request.
  • Notice. Except in circumstances where we are instructed by appropriate legal authority not to notify, are prohibited from doing so, or there is a clear indication of illegal or malicious conduct or risk of harm, we will notify the user of a request before disclosing any information that may be available (as specified in Paragraph 2 above), so that the user may seek available legal remedies.

5. How to Submit a Request

To be processed, all requests must be formal, written on official agency letterhead, and sent from an official government email address to privacy@kinfide.com.

While we agree to accept requests by this method, neither we nor our users waive any legal rights based on this accommodation.